type md_ctrl_exec, exec_type, file_type; type md_ctrl, domain, domain_deprecated; init_daemon_domain(md_ctrl) allow md_ctrl ccci_device:chr_file rw_file_perms; allow md_ctrl devpts:chr_file rw_file_perms; allow md_ctrl muxreport_exec:file rx_file_perms; allow md_ctrl self:capability dac_override; # sysfs_ccci allow md_ctrl sysfs_ccci:dir { r_file_perms search }; allow md_ctrl sysfs_ccci:file r_file_perms; set_prop(md_ctrl,vold_encryption_type_prop);